PT-2005-1061 · None+1 · Util-Linux+1

David Watson

·

Published

2005-09-13

·

Updated

2018-10-19

·

CVE-2005-2876

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions util-linux versions 2.8 through 2.12q util-linux versions 2.13-pre1 through 2.13-pre2 Red Hat Enterprise Linux (affected versions not specified)
Description The issue concerns multiple vulnerabilities in the util-linux package and Red Hat Enterprise Linux, which can be exploited locally to compromise the confidentiality, integrity, and availability of protected information. The exploitation can be achieved through the umount function in util-linux, allowing local users with unmount permissions to gain privileges via the -r (remount) option. This option causes the file system to be remounted with just the read-only flag, effectively clearing the nosuid, nodev, and other flags.
Recommendations For util-linux versions 2.8 through 2.12q and 2.13-pre1 through 2.13-pre2, consider disabling the -r (remount) option in the umount function to prevent privilege escalation. For Red Hat Enterprise Linux, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-06016
BDU:2015-06017
BDU:2015-06018
BDU:2015-06019
BDU:2015-06075
CVE-2005-2876
DSA-823-1
DSA-825-1
RHSA-2005:782
RHSA-2005_782

Affected Products

Red Hat
Util-Linux